From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id EB07C34040D for ; Tue, 11 Aug 2026 14:19:54 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786457996; cv=none; b=PYt6NnR/KVLIHoyhXJ4ydAoSI7uea5L7tBtD0mt/xEo1OX09oB2tejRXelNQJqTCqVKJ0IK/VVoU3kjE0RQ+UmagzxSllexHYKqu3zb4z17qV55OOKary5acCYhXUjQu7miR9aldxbXVplKUFxq+dAOL33mBpxvnkpLMIA0ut1Y= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786457996; c=relaxed/simple; bh=sZqAOZ/9fXSSMopelUacurxkDg55h746+b9Laj4n0To=; h=MIME-Version:Date:From:To:Cc:Message-Id:In-Reply-To:References: Subject:Content-Type; b=aiHeZROKVzZn0IrIqAZE4u+OE24LWjLMcbdSHO1vORmpTyA7FPriJU+YD2AKfb7GZrWwXqTkgb7KTfoqSpIGr+bby9nerOx66ILou3x92olG8wkpJv8IpcmN4wIYnBcWYQLHdyTsZdyTIkXaAXXn6Y/wWfl5bamZpq9A4Dgv5/Y= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b=VAL3NnWr; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=kernel.org header.i=@kernel.org header.b="VAL3NnWr" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 568441F000E9 for ; Tue, 11 Aug 2026 14:19:54 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=kernel.org; s=k20260515; t=1786457994; bh=HbEoHeWa1iXbv+CJsuBzx8OY0CDSunFEVpuvSAPhmGU=; h=Date:From:To:Cc:In-Reply-To:References:Subject; b=VAL3NnWr4vD7qt7VGFKNxRnFzje/ffHpkSssI67BzAEI6IPyJFXDzHcCCyjI2Ht3n LEE8HrSS0M2eTQJd3FT/fIrTnzrtLSPQGR4eUnaYauubjmxs95MgMaifp4YzOyuCTT 1146Odr5ZpH9o5q5XZLhfP8n39Twi5J2181RdJddSSif/dOw/DvNXEeXFxrg5i1JBx 2urg1xF8pdtp5Uwa1QhmL1XUVqtBXREjr1uLUDFezTTMq31qmrWbzcazxgqQPdDpVm 3UwaZTH0hx51/O7sa08twvQY9ixynLPByb9Y/uKx+qZ7MD0QyZsX/h5fhx4PjhgHo5 3r3cSrG0FAhoA== Received: from ams-compute-02.internal (ams-compute-02.internal [10.64.2.62]) by mailfauth.ams.internal (Postfix) with ESMTP id DDE631980047; Tue, 11 Aug 2026 10:19:52 -0400 (EDT) Received: from ams-imap-11 ([10.64.2.31]) by ams-compute-02.internal (MEProxy); Tue, 11 Aug 2026 10:19:52 -0400 X-ME-Sender: X-ME-Proxy-Cause: dmFkZTE9VSS85hDKObpVcqPkq+33i6ZXW5fVUmYbaU57hGElAJcK+GHLt6B/EQSqfeZrx5 Q/ode+btOhPbFNAdyaT3DsQWNimOmiaFKmTUQtWe/kYCuKs6ApVUrCs5uFyNz9pdqwdfW1 rd8vllQY1Lymp6SIqWfrj3Xm9t/ErLKGHiBxJNvn2AkkU2X8/rrKjLk2Oo4U0nultql5Wt SE0fH2j1uQYRGtc9+ZWibx9Z/w0suyUbs/FfYCWhnBxMbYKVbPy1ad8W6zb2SlJ0GgWD2A t1dp3GloUHUCE2cxugLFj+b70RJmFEhNSrYTHC/uwtF367cNHf3CdfvrFlNy6ZnMDmlLDe QosOPqu3JcJBWh2M4deiatVk3DWdpV4PlwKzvmkXPxhVQcf6eEtHFdJWnh0fjyqTUcPOUH 1iwTwMOX9Y74xBrGIbQJrxscrmCPvhY1dTQZ35E58fzw14AYOITJliZzgrzY+KstXKQf6B HMRaOyl+duaEGH2DRjAOba4dha/XmaEW6aOuEx4uS73u8f2Nm0rJ6tygG26rUeoYs/vFfw x+HqNu/078HyCyTzaK5aDOzsJvCPNiG2mwoda2IHkE5bGFCnMrFo3WoBSF2pGNlx7mehZz k7SyIQ1nCuO0PKf2hu9P0FqY5+kkPGjdGErmbf1lfSLMsH51MzOH7vZ7wcoQ X-ME-Proxy: Feedback-ID: ice86485a:Fastmail Received: by mailuser.ams.internal (Postfix, from userid 501) id 3954AF8006A; Tue, 11 Aug 2026 10:19:51 -0400 (EDT) X-Mailer: MessagingEngine.com Webmail Interface Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Date: Tue, 11 Aug 2026 16:19:30 +0200 From: "Ard Biesheuvel" To: "Will Deacon" , linux-arm-kernel@lists.infradead.org Cc: linux-kernel@vger.kernel.org, "gus bourg" Message-Id: In-Reply-To: <20260811140430.22832-1-will@kernel.org> References: <20260811140430.22832-1-will@kernel.org> Subject: Re: [PATCH] arm64/efi: Avoid voluntary preemption with efi_mm installed Content-Type: text/plain Content-Transfer-Encoding: 7bit On Tue, 11 Aug 2026, at 16:04, Will Deacon wrote: > Gus reports a bad kernel memory access when using software PAN > (CONFIG_ARM64_SW_TTBR0_PAN=y) on a machine with support for EFI runtime > services: > > Unable to handle kernel access to user memory outside uaccess routines > at virtual address 00000000f322ff30 > Mem abort info: > ESR = 0x0000000096000004 > FSC = 0x04: level 0 translation fault > Internal error: Oops: 0000000096000004 [#1] SMP > Workqueue: efi_rts_wq efi_call_rts > pstate: 80400005 (Nzcv daif +PAN -UAO -TCO -DIT -SSBS BTYPE=--) > pc : efi_call_rts+0xd8/0x288 > Call trace: > efi_call_rts+0xd8/0x288 (P) > process_one_work+0x178/0x4f8 > worker_thread+0x194/0x328 > > This is because the fpsimd context management code called from > __efi_fpsimd_begin() can preempt voluntarily, returning later to the EFI > code with an incorrect value for TTBR0_EL1 thanks to the deferred mm > switching used by the software PAN implementation. > > Since EFI runtime services cannot preempt voluntarily and because the > fpsimd switching code does not rely on the TTBR0_EL1 mappings, simply > reorder the fpsimd switch so that it occurs before we change the > page-table. > > Cc: Ard Biesheuvel > Reported-by: Gus Bourg > Tested-by: Gus Bourg > Fixes: a5baf582f4c0 ("arm64/efi: Call EFI runtime services without > disabling preemption") > Link: > https://lore.kernel.org/all/20260806000144.3388823-1-gus@bourg.net/ > Signed-off-by: Will Deacon Reviewed-by: Ard Biesheuvel